Fake CAPTCHA Pushes Psychedelic Stealer Through Compromised Ukrainian Websites

Compromised Ukrainian sites show fake Cloudflare CAPTCHA that tricks users into running msiexec to install Psychedelic Stealer stealing logins and wallets.

Fake CAPTCHA Pushes Psychedelic Stealer Through Compromised Ukrainian Websites
Malware

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Legitimate sites become the first stage of the attack

A ClickFix campaign is abusing compromised Ukrainian business websites to distribute an information-stealing implant known as Psychedelic Stealer.

Visitors encounter a fraudulent Cloudflare-style verification page loaded through a hidden iframe. The affected sites belong to established businesses, including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer.

Their existing social-media accounts and third-party listings may make the sites appear trustworthy to returning customers. The websites themselves are therefore part of the deception: users are more likely to follow an unusual verification request when it appears on a business they recognize.

The fake page is written in Ukrainian and includes visual details intended to resemble Cloudflare infrastructure. Its footer generates a random hexadecimal “Ray ID,” while the agreement text displays a fixed “visitor identifier.” Neither value proves that Cloudflare processed the request.

Researchers also found Russian-language comments in the HTML and a lang="ru" declaration. Those artifacts could reflect how the page was developed, but they do not establish the attackers’ nationality, location, or organizational affiliation.

The campaign was reported by Arctic Wolf Labs on September 25, 2026.

A clipboard trick launches Windows Installer

The delivery chain depends on convincing the victim to execute the malware rather than exploiting a software vulnerability.

When a visitor clicks the displayed CAPTCHA, JavaScript silently copies a Windows Installer command to the clipboard. The page then instructs the user to press Windows+R, paste the copied content into the Run dialog, and press Enter.

Fake Cloudflare verification text embedded in the command helps preserve the illusion that this is a legitimate validation step. In reality, the command directly launches the native Windows utility msiexec.exe, which retrieves or installs the malicious MSI package.

The MSI subsequently installs psychedeliclove.exe, a 64-bit executable tracked as Psychedelic Stealer.

This initial sequence does not invoke PowerShell. That distinction matters because security policies and behavioral detections often treat PowerShell as a high-risk interpreter. By starting with msiexec.exe, the attackers may avoid controls narrowly configured to detect PowerShell-based ClickFix activity.

The approach also bypasses a common user expectation. Clicking a real CAPTCHA should never require opening the Windows Run dialog or manually executing clipboard content. The request itself is a strong warning sign.

Psychedelic Stealer targets credentials, tokens, and wallets

Once installed, Psychedelic Stealer searches for saved passwords and account tokens held by several Chromium-based and related browsers. Its documented targets are:

  • Chrome
  • Edge
  • Brave
  • Opera
  • Opera GX
  • Vivaldi
  • Yandex

The malware also looks for data belonging to cryptocurrency applications, including Exodus, Atomic Wallet, Electrum, Bitcoin Core, and Litecoin Core. Theft from these applications could expose wallet information or other sensitive material, depending on what is stored on the infected device.

Its capabilities extend beyond credential collection. The implant profiles the host, gathering information such as installed browsers and antivirus status. It also installs browser components and creates a native messaging bridge, allowing deployed browser content to communicate with a local process.

For persistence, Psychedelic Stealer creates a scheduled task named:

psychedelicloveUtils

The malware then polls its command-and-control infrastructure for further instructions. It records task status in:

executed_tasks.json

Files supplied through the tasking system are stored using the following directory and naming structure:

downloads\<taskid>_<filename>

Supported payload formats include EXE, COM, BAT, CMD, MSI, and PowerShell files. PowerShell may therefore appear after infection even though it is absent from the first-stage delivery chain.

This task mechanism turns the stealer into a platform for follow-on intrusion. Operators could use an infected computer to run additional tools or malware, rather than stopping after browser and wallet data are collected.

Rublevka TDS centralizes campaign control

The attackers manage the operation through a panel named “РУБЛЁВКА TDS” (Rublevka TDS), a reference to the wealthy Rublevka area near Moscow.

The panel lets operators replace the Windows Installer command delivered by compromised sites without modifying every injected page. That centralized design allows the delivery payload or installation instructions to change while the website compromises remain in place.

Rublevka TDS also records several stages of user interaction:

  1. Opening the malicious page.
  2. Clicking the fake CAPTCHA.
  3. Clicking the Done button after following the displayed instructions.

The Done button remains disabled for approximately 35 seconds after the command is copied. This delay gives a visitor time to open the Run dialog, paste the command, and attempt to execute it.

At the time the activity was collected, the panel showed 557 views, 426 CAPTCHA clicks, and 79 complete events across 32 countries. Ukraine accounted for 446 views and 351 clicks, making it the dominant observed location.

Those numbers require careful interpretation. The panel calls complete events “executions” and uses them to calculate a conversion rate, but a complete event only establishes that someone clicked Done in the browser. It does not prove that msiexec.exe ran successfully, the MSI was installed, or the host was compromised.

The confirmed infection count is therefore unknown.

Infrastructure appeared shortly before delivery activity

The campaign’s central domain was:

uasputnik[.]com

It was registered on September 9, 2026, and updated three and a half hours later. Associated lure URLs appeared on September 12 and 13, 2026.

That sequence places the observed preparation and delivery activity within a short operational window. However, the available evidence does not establish who registered the infrastructure or how the Ukrainian business websites were initially compromised.

No vulnerability, CVE identifier, or exploit used against those sites has been disclosed. The affected content management systems, hosting platforms, and website versions are also not known.

Similarly, no formal severity rating or CVSS score applies to the campaign. Its risk instead comes from the combination of social engineering, credential theft, cryptocurrency targeting, persistence, and remote task execution.

Detection should combine network, process, and file evidence

Defenders should look for traffic to the initial campaign domain, particularly requests involving:

uasputnik[.]com
admin777111777.php

Potential later-stage command-and-control activity includes connections to:

193.178.159[.]128:8080

Relevant request paths include:

/api/v1/agent/
/api/v1/ext/

Requests carrying an X-API-Key header may provide additional context when investigating this traffic.

Endpoint teams should also search for:

  • Creation or execution of psychedeliclove.exe.
  • A scheduled task named psychedelicloveUtils.
  • The files or paths executed_tasks.json and downloads\<taskid>_<filename>.
  • Unexpected msiexec.exe activity following browser interaction.
  • MSI installation initiated through the Windows Run dialog.
  • Browser components communicating with local processes through native messaging.
  • Subsequent EXE, COM, BAT, CMD, MSI, or PowerShell payloads associated with the implant.

A network match alone does not necessarily prove infection. Analysts should correlate domain or IP connections with clipboard-related user activity, msiexec.exe execution, file creation, scheduled-task registration, and outbound C2 requests.

No vendor-issued patch, specific cleanup utility, or documented remediation procedure is available. Potentially affected systems should be isolated and investigated before credentials are reset. Because the malware targets browser secrets and account tokens, responders should consider invalidating active sessions as well as changing passwords. Cryptocurrency applications on confirmed infected hosts require separate review for possible exposure.

The most direct preventive control is user-facing: a CAPTCHA that asks someone to press Windows+R and execute pasted content is not a verification process. It is an instruction to run code.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →